CVE-2007-3747

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
3 August 2007

Summary

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.